CVE-2023-0628

CVSS V2 None CVSS V3 None
Description
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
Overview
  • CVE ID
  • CVE-2023-0628
  • Assigner
  • security@docker.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-13T12:15:10
  • Last Modified Date
  • 2023-03-17T03:50:01
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:docker:docker_desktop:*:*:*:*:*:*:*:* 1 OR 4.17.0
References
Reference URL Reference Tags
https://docs.docker.com/desktop/release-notes/#4170 Release Notes
History
Created Old Value New Value Data Type Notes
2023-04-17 06:19:23 Added to TrackCVE
2023-04-17 06:19:24 Weakness Enumeration new